[Android 5.15] BUG: workqueue lockup

5 views
Skip to first unread message

syzbot

unread,
Jun 22, 2023, 6:20:00 PM6/22/23
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 565c3abfa129 Merge 5.15.110 into android13-5.15-lts
git tree: android13-5.15-lts
console output: https://syzkaller.appspot.com/x/log.txt?x=115ffe1f280000
kernel config: https://syzkaller.appspot.com/x/.config?x=ecfd0037bd0e156c
dashboard link: https://syzkaller.appspot.com/bug?extid=2499e5a71acdc2680959
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16dc0f60a80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10526123280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b5fe0afff919/disk-565c3abf.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/99229c5c028f/vmlinux-565c3abf.xz
kernel image: https://storage.googleapis.com/syzbot-assets/087beb6c80ec/bzImage-565c3abf.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2499e5...@syzkaller.appspotmail.com

RBP: 00007f58acd574d8 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f58acd574d0
R13: 00007f58acd23664 R14: 00007f58acc58400 R15: 0000000000022000
</TASK>
BUG: workqueue lockup - pool cpus=0 node=0 flags=0x1 nice=0 stuck for 242s!
BUG: workqueue lockup - pool cpus=0 node=0 flags=0x0 nice=-20 stuck for 236s!
BUG: workqueue lockup - pool cpus=1 node=0 flags=0x1 nice=0 stuck for 242s!
BUG: workqueue lockup - pool cpus=0-1 flags=0x4 nice=0 stuck for 242s!
Showing busy workqueues and worker pools:
workqueue events: flags=0x0
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=3/256 refcnt=4
pending: kfree_rcu_work, kfree_rcu_monitor, rht_deferred_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=2/256 refcnt=3
pending: vmstat_shepherd, psi_avgs_work
workqueue events_long: flags=0x0
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=5/256 refcnt=6
pending: br_fdb_cleanup, br_fdb_cleanup, br_multicast_gc_work, br_multicast_gc_work, br_multicast_gc_work
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=6/256 refcnt=7
pending: br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup, br_multicast_gc_work, br_multicast_gc_work
workqueue events_unbound: flags=0x2
pwq 4: cpus=0-1 flags=0x4 nice=0 active=2/512 refcnt=4
pending: toggle_allocation_gate, flush_memcg_stats_dwork
workqueue events_power_efficient: flags=0x80
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=3/256 refcnt=4
pending: gc_worker, neigh_periodic_work, neigh_periodic_work
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=2/256 refcnt=3
pending: wg_ratelimiter_gc_entries, check_lifetime
workqueue mm_percpu_wq: flags=0x8
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: vmstat_update
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: vmstat_update
workqueue writeback: flags=0x4a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wb_workfn
workqueue kblockd: flags=0x18
pwq 1: cpus=0 node=0 flags=0x0 nice=-20 active=1/256 refcnt=2
pending: blk_mq_timeout_work
workqueue dm_bufio_cache: flags=0x8
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: work_fn
workqueue mld: flags=0x40008
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/1 refcnt=19
pending: mld_dad_work
inactive: mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_dad_work, mld_ifc_work, mld_dad_work
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/1 refcnt=3
pending: mld_dad_work
inactive: mld_dad_work
workqueue ipv6_addrconf: flags=0x40008
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/1 refcnt=159
in-flight: 60:addrconf_dad_work
inactive: addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work
, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work
, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work
, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work, addrconf_dad_work
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/1 refcnt=2
pending: addrconf_verify_work
workqueue wg-kex-wg0: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x28
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x28
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
in-flight: 1077:wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
in-flight: 1054:wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_tx_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=2/256 refcnt=4
pending: wg_packet_handshake_send_worker, wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_decrypt_worker
workqueue wg-kex-wg2: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-kex-wg1: flags=0x24
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg1: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=2/256 refcnt=4
pending: wg_packet_handshake_send_worker, wg_packet_handshake_send_worker
workqueue wg-kex-wg2: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=2/256 refcnt=4
pending: wg_packet_handshake_send_worker, wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
in-flight: 1061:wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x24
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg1: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x24
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg0: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x24
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg2: flags=0x6
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/256 refcnt=3
pending: wg_packet_handshake_send_worker
workqueue wg-kex-wg1: flags=0x24
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg2: flags=0x24
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg2: flags=0x28
pwq 2: cpus=1 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
pwq 0: cpus=0 node=0 flags=0x1 nice=0 active=1/256 refcnt=2
pending: wg_packet_encrypt_worker
pool 0: cpus=0 node=0 flags=0x1 nice=0 hung=243s workers=5 manager: 6 idle: 20 1095 1032 1053
pool 2: cpus=1 node=0 flags=0x1 nice=0 hung=0s workers=6 manager: 1052 idle: 39
pool 4: cpus=0-1 flags=0x4 nice=0 hung=0s workers=5 idle: 884 45 568


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages